Live data from Hacker News

Path uploads your entire iPhone address book to its servers

mclov.in

191–200 of 283 posts

Re: Path uploads your entire iPhone address book to its servers

#191
post #126

Earlier quoted context omitted.

While I still support Path, the best PR move they could do right now is to pro-actively wipe all non-members' contact info from their servers, and then fast-track approval of the new "opt-in" version to the App Store, so that users can re-upload. Played right, this episode could actually give them free publicity. Companies like Facebook and Zynga have been embroiled in far worse controversies, and they've all blown o…

That's not a PR move, that's what you do while crossing your fingers that state attorney generals and the FTC doesn't come after you.

Yes, good point. And regarding state attorney generals, how is this not data theft? It seems to go far beyond privacy issues, the program is in every way that matters a trojan that steals personal data. I can't see how it could not be considered so given the details of what was discovered.

Re: Path uploads your entire iPhone address book to its servers

#192
post #103

I find it mind blowing that (in the comments of the blog post) someone asked the Path CEO: > Why wasn't this [sending all the contacts to your servers without users knowing] an opt-in situation to begin with? Isn't that against Apple's own T&Cs? and the Path CEO replied: > This is currently the industry best practice and the App Store guidelines do not specifically discuss contact information. However, as mentioned,…

Wait: What about MY INFORMATION if I've never installed Path? If someone I know with my contact information installs Path, does that mean that my information is stored on their servers? How can I remove my information if I've never installed Path before? It doesn't seem right that my contact information, which I have kept private, because someone I know has uploaded that information. Do I not have a right to keep tha…

Clearly there are a lot of WTFs going on at Path, but this isn't one of them.

> Do I not have a right to keep that information private?

But you didn't. You gave it to someone else. It's not your information any more.

Information about you is not information you own.

Privacy and anti-spam laws in various jurisdictions cover what an organisation can do with information they collect about private individuals, but that has nothing to do with ownership.

Re: Path uploads your entire iPhone address book to its servers

#193

So does Facebook, as shown 107 days ago, and continuing today. http://news.ycombinator.com/item?id=3145857

Yeah, I've noticed that too. After my first sync with Yahoo! Address book years ago, I ended up getting Facebook suggestions to people I didn't really know but who were in my Yahoo! address book.

Re: Path uploads your entire iPhone address book to its servers

#194
post #128

Earlier quoted context omitted.

If I were involved in this (and I'm not, I just think transparency - not privacy - matters) I would want the CEO and CTO of Path to create a video that is displayed to all relevant users in their mobile app. The first thing they do is apologise, they explain in plain words what people are up in arms about, the CTO reiterates that a) this was dumb and a poor choice but we are all human, b) what this means (eg: we did…

I would want the CEO to: 1) Immediately delete all of the non-user data 2) Send an apology e-mail to each Path user explaining the situation 3) Write, by hand, a corresponding apology letter for each Path user 4) Hold a townhall-style meeting in which members of the public can ask him questions 5) Pay, out of pocket, the travel expenses of anyone who attends the townhall meeting 6) Wear an indicator of shame (large n…

Regardless of how bad what they were doing was, I don't think any of these except #2 are really realistic.

A good email explaining what they were doing, why and how they are going to correct it in the future should be sufficient.

Damage control should be "Oh crap, sorry we were just so dumb that we overlooked it" (which is most likely the case) Flat out honesty is the best way to go here. (unless they were up to no good.. then well they deserve what they get)

Re: Path uploads your entire iPhone address book to its servers

#195

> industry best practice Did he say that with a straight face? Heard a lot of corporate BS in my time but this takes the cake. This is Apple's fault for allowing all apps access to the address book. But there is a deeper issue here, trust. Just because I leave my office unlocked doesn't mean my colleagues can steal from it. I love this app and had great hopes for it but trust is a limited commodity and Path just lost…

There's a dozen or so people right in this discussion that are repeating it with a straight face, that this behavior is normal and acceptable.

I know for a fact it is illegal in Europe, know for a fact it is a violation of their contract with Apple, and I am almost positive it is criminal in the US as well.

Therefore the names and affiliations of the engineers here who are claiming data theft of private information is normal are very interesting to me, and I am noting them carefully, as should we all.

Re: Path uploads your entire iPhone address book to its servers

#196

Earlier quoted context omitted.

I've just: 1) saved their Privacy Policy and Terms of Use 2) requested a complete deletion of our family's account 3) requested deletion of any/all stored information 4) considering contacting our lawyer As I emailed to Path's support, our 3-4 year old children's schools, bus companies, physicians, pharmacies and our family lawyer were in that contact list - that's an insane, willful, and quite unexpected violation o…

considering contacting our lawyer What do you expect to achieve with this step?

To get his money back, of course.

Re: Path uploads your entire iPhone address book to its servers

#197
post #44

Dave Morin, Path's CEO just responded in a comment: http://mclov.in/2012/02/08/path-uploads-your-entire-address-... > Arun, thanks for pointing this out. We actually think this is an important conversation and take this very seriously. We upload the address book to our servers in order to help the user find and connect to their friends and family on Path quickly and effeciently as well as to notify them when friends…

>we proactively rolled out an opt-in for this on our Android client a few weeks ago and are rolling out the opt-in for this in 2.0.6 of our iOS Client, pending App Store approval. "Proactively?" How do you get into the Social Networking business and not see this issue coming before the first line of code is written? [re: hashing] >This is a good alternative solution which we'll look into. Thanks for the idea. Again,…

> How do you get into the Social Networking business and not see this issue coming before the first line of code is written?

"It is difficult to get a man to understand something, when his salary depends upon his not understanding it." -- Upton Sinclair (http://en.wikiquote.org/wiki/Upton_Sinclair)

Re: Path uploads your entire iPhone address book to its servers

#198

It would be nice to go a single week without seeing how utterly complete the notion of privacy has been destroyed.

The responsibility entirely rests in a large part on the shoulders of the geek community - the enablers. I find this entire thread surreal. These were the obvious issues that were front and center way back when chat servers showed up. Some have been raising this issue both publicly and privately since early 90s if not earlier and were marginalized precisely for being bad news bears.

Here is to RMS and his kind.

At this point, if you want a solution, you need to contact your representative and demand data and electronic privacy laws like that which is written in the constitution of Switzerland.

Re: Path uploads your entire iPhone address book to its servers

#200
post #103

I find it mind blowing that (in the comments of the blog post) someone asked the Path CEO: > Why wasn't this [sending all the contacts to your servers without users knowing] an opt-in situation to begin with? Isn't that against Apple's own T&Cs? and the Path CEO replied: > This is currently the industry best practice and the App Store guidelines do not specifically discuss contact information. However, as mentioned,…

Wait: What about MY INFORMATION if I've never installed Path? If someone I know with my contact information installs Path, does that mean that my information is stored on their servers? How can I remove my information if I've never installed Path before? It doesn't seem right that my contact information, which I have kept private, because someone I know has uploaded that information. Do I not have a right to keep tha…

"Do I not have a right to keep that information private?"

Generally no. I mean anyone can put their in law's information on their blog. It's a dick move but not illegal generally (if you're putting the person in danger like an battered spouse or witness protection there may be problems, IANAL).

I get the outrage that they didn't hash everything but the righteous indignation that a social network is trying their best to let people know when their friends sign up seems overblown.

Moral of the story: don't be shocked when social networks don't follow best practices for privacy. Also foxes like chickens.

If they're smart they'll revamp their system to work like this:

edit: (0) we get your permission /edit

(1) we check for your contacts in our database (hashing your contacts).

(2) we let you know if any matches are found.

(3) we throw away all your data afterwords.

They'll generate a few fewer matches this way but since they're going for stronger ties it shouldn't really be an issue.

Post reply on HN